| Version | Supported |
|---|---|
The deployed main branch |
Yes |
| Older commits, branches, and previews | No |
Use GitHub Private Vulnerability Reporting for suspected vulnerabilities.
Do not publish secrets, personal data, exploit details, or reproduction material in a public issue. Public issues may be used only for non-sensitive security improvements.
A useful private report includes:
- a concise summary and the affected route or component;
- the observed and expected behavior;
- safe reproduction steps or a minimal proof of concept;
- the likely impact and prerequisites;
- relevant browser, runtime, and commit information;
- any mitigation already tested.
Maintainers will review private reports, request clarification when needed, and communicate remediation or disclosure decisions as availability permits. This policy does not promise a fixed response or resolution deadline.